CVE-2019-12402

Description

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.382

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-12402 are fixed in Apache-commons-compress 1.19Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 18.0.0.0Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 18.0.0.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.0.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.12.0.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.1.0Windows
Vulnerabilities CVE-2019-12402 are affected in Github - commons-compress 1.18.1Windows
Vulnerabilities CVE-2019-12402 are fixed in Apache-commons-compress for Linux 1.19Linux
Vulnerabilities CVE-2019-12402 are affected in Github - commons-compress for Linux 1.18.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234